Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%💥 Exploit4homepages 4images8/2/201216/6/2026
SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.
ModificadaMedia (4.3)1.5%💥 Exploit4homepages 4images8/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.
ModificadaMedia (4.3)1.5%💥 ExploitLeadcapturepagesystem Lead Capture Page System29/1/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaMedia (5)22%💥 ExploitMikoviny WP Custom Pages10/4/201116/6/2026
Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.
ModificadaAlta (7.5)0.92%💥 ExploitSmspages9/7/200916/6/2026
SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
ModificadaMedia (4.3)1.1%—4homepages 4images8/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the url variable.
ModificadaMedia (6.8)2.1%💥 Exploit4homepages 4images19/6/200916/6/2026
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter.
ModificadaBaja (3.5)1.6%💥 Exploit4homepages 4images19/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture.
ModificadaAlta (7.5)0.97%💥 ExploitMybboard Custom Pages Plugin20/2/200916/6/2026
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaMedia (4.3)1.0%—Hitachi Groupmax WEB Workflow SDK SET FOR Active Server PagesHitachi Groupmax Workflow TO Development KIT FOR Active Server Pages26/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in Hitachi Groupmax Web Workflow SDK Set for Active Server Pages before 06-52-/C and Hitachi Groupmax Workflow - Development Kit for Active Server Pages before 06-52-/A allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.2%💥 ExploitMyiosoft Easydynamicpages28/7/200816/6/2026
SQL injection vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to execute arbitrary SQL commands via the read parameter.
ModificadaMedia (4.3)1.3%—Myiosoft Easydynamicpages28/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the year parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPagesquid CMS27/6/200816/6/2026
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaAlta (9.3)16%💥 ExploitPagesperso-orange GFL SDKPagesperso-orange NconvertPagesperso-orange Xnview24/6/200816/6/2026
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.
ModificadaAlta (7.5)3.2%—SUN Java Active Server Pages4/6/200816/6/2026
Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications.
ModificadaAlta (7.5)46%💥 ExploitSstreamtv Custompages25/3/200816/6/2026
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php.
ModificadaMedia (5)4.5%💥 ExploitPostnuke Software Foundation Pagesetter2/3/200716/6/2026
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitDesign4online Userpages222/2/200716/6/2026
SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.1%💥 ExploitEnthrallweb Epages28/12/200616/6/2026
SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.
ModificadaAlta (7.5)2.1%💥 Exploit4homepages 4images11/10/200616/6/2026
SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter.
ModificadaMedia (6.8)11%💥 ExploitUser Home Pages5/8/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to…
ModificadaBaja (2.6)1.3%—4homepages 4images25/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.
ModificadaAlta (7.5)4.9%—Secure Reality Phpsecurepages13/7/200516/6/2026
PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.
ModificadaAlta (7.5)8.8%💥 ExploitStoitsov Easydynamicpages17/2/200416/6/2026
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.
ModificadaAlta (7.5)1.9%—Secure Reality Phpsecurepages7/2/200116/6/2026
PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.
Orbitaley — Vulnerabilidades